Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2024-32007

Опубликовано: 19 июл. 2024
Источник: redhat
CVSS3: 7.5

Описание

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

An improper input validation vulnerability was found in the p2c parameter in the Apache CXF JOSE. This flaw allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token.

Отчет

The improper input validation vulnerability in the p2c parameter of Apache CXF JOSE is considered a moderate severity issue rather than a important one due to its limited scope and impact. While the flaw allows an attacker to specify a large value for the p2c parameter, leading to potential denial of service (DoS) attacks by causing excessive computational overhead, it does not compromise data integrity, confidentiality, or authentication mechanisms directly. The attack vector primarily affects system availability and exploiting this vulnerability requires the ability to send crafted tokens. Base EAP (7.4 and 8) and EAP XP (4 and 5) do not ship this affected CXF jaxrs artifact. cxf-rt-rs-security-jose is part of CXF's JAX-RS, and EAP uses RESTEasy, hence it's not-affected.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat build of Apache Camel for Spring Boot 3org.apache.cxf/cxf-rt-rs-security-joseAffected
Red Hat build of Quarkusorg.apache.cxf/cxf-rt-rs-security-joseWill not fix
Red Hat Fuse 7org.apache.cxf/cxf-rt-rs-security-joseAffected
Red Hat Integration Camel K 1org.apache.cxf/cxf-rt-rs-security-joseWill not fix
Red Hat JBoss Data Grid 7org.apache.cxf/cxf-rt-rs-security-joseWill not fix
Red Hat JBoss Enterprise Application Platform 7org.apache.cxf/cxf-rt-rs-security-joseNot affected
Red Hat JBoss Enterprise Application Platform 8org.apache.cxf/cxf-rt-rs-security-joseNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packorg.apache.cxf/cxf-rt-rs-security-joseNot affected
Red Hat build of Apache Camel 3.20.7 for Spring Bootorg.apache.cxf/cxf-rt-rs-security-joseFixedRHSA-2024:688319.09.2024
Red Hat build of Apache Camel 4.4.0 for Spring BootFixedRHSA-2024:270706.05.2024

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
Дефект:
CWE-400
https://bugzilla.redhat.com/show_bug.cgi?id=2298828apache: cxf: org.apache.cxf:cxf-rt-rs-security-jose: Denial of Service vulnerability in JOSE

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
больше 1 года назад

An improper input validation of the p2c parameter in the Apache CXF JOSE code before 4.0.5, 3.6.4 and 3.5.9 allows an attacker to perform a denial of service attack by specifying a large value for this parameter in a token. 

CVSS3: 5.3
github
больше 1 года назад

Apache CXF Denial of Service vulnerability in JOSE

CVSS3: 7.5
fstec
больше 1 года назад

Уязвимость компонента JOSE каркаса для веб-сервисов Apache CXF, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3